Skip to content
HighVulnerability

CVE-2026-93443: IBM Langflow OSS remote code execution by authenticated attacker

Identifier
CVE-2026-93443
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain CVE-2026-93443. A remote authenticated attacker can exploit improper neutralization of special elements used in code to execute arbitrary code.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.